Daily Open Source Infrastructure Report 05 August 2013 Top Stories • A former trader at Goldman Sachs was found liable in a U.S. Securities and Exchange Commission lawsuit for misleading investors about subprime mortgage securities during the 2007 mortgage crisis, making $1 billion in profits for his employer. – Associated Press (See item 7) • Firefighters reached 45 percent containment of the 16,200-acre Aspen Fire in Fresno County, California, August 1. – Modesto Bee (See item 25) • Crews continued to battle the 72,000-acre Colockum Tarps Fire in Kittitas County, Washington, August 1 and evacuations were ordered for several other residences around the county while firefighters worked to establish containment lines. – Wenatchee World (See item 27) • The U.S. Department of Labor’s Occupational Safety and Health Administration found several violations August 1 at an Army weapons-testing pond in Aberdeen, Maryland, where 3 people have died in 2013. – Associated Press (See item 29) Fast Jump Menu PRODUCTION INDUSTRIES • Energy • Chemical • Nuclear Reactors, Materials, and Waste • Critical Manufacturing • Defense Industrial Base • Dams SUSTENANCE and HEALTH • Food and Agriculture • Water and Wastewater Systems • Healthcare and Public Health SERVICE INDUSTRIES • Financial Services • Transportation Systems • Information Technology • Communications • Commercial Facilities FEDERAL and STATE • Government Facilities • Emergency Services -1- Energy Sector 1. August 2, Daytona Beach News-Journal – (Florida) FPL: Outage hits 110,000 customers. Florida Power & Light Co. crews worked to restore service to 110,000 customers on Volusia’s east side August 1. The cause of the outage was being investigated. Source: http://www.newsjournalonline.com/article/20130801/NEWS/130809898/1040?Title=FPL-Outage-hits110-000-customers-&tc=ar 2. August 1, Reuters – (Arkansas) Decades-old defect caused Exxon’s Atkansas oil spill: regulator. Officials with the U.S. Pipeline and Hazardous Materials Safety Administration said August 1 that a leak in Exxon Mobil Corp’s Pegasus pipeline, which spilled about 5,000 barrels of crude oil in Mayflower, Arkansas, in March was caused by an original manufacturing defect. The report stated it was likely some microcracking may have occurred immediately following the pipe’s manufacturing which led to further cracking over time. Source: http://www.chicagotribune.com/business/sns-rt-us-usa-pipeline-exxon20130801,0,7710357.story 3. August 1, The Register – (International) Hackers induce ‘CATASTROPHIC FAILURE’ in mock oil well. Researchers with Cimation demonstrated how to exploit widely deployed supervisory control and data acquisition (SCADA) systems to spoof data to the operator and remotely control equipment such as pumps in oil pipelines. A programmable logic controller was remotely controlled to send signals to devices on the simulated pipeline, allowing researchers the ability to turn pumps on and off, causing the mock oil pipeline to rupture. Source: http://www.theregister.co.uk/2013/08/01/scada_plc_vulnerability/ [Return to top] Chemical Industry Sector See item 24 [Return to top] Nuclear Reactors, Materials, and Waste Sector 4. August 1, Associated Press – (Florida) Duke Energy won’t build Levy County nuclear plant. Duke Energy Corp. announced that they were canceling plans to build a new nuclear power plant in Levy County, though they are still pursuing a U.S. Nuclear Regulatory Commission license for possible future projects. Source: http://www.abcactionnews.com/dpp/news/region_south_pinellas/st_petersburg/dukeenergy-wont-build-levy-county-nuclear-plant -2- [Return to top] Critical Manufacturing Sector 5. August 1, U.S. Department of Labor – (Guam) Guam Shipyard cited with 61 repeat, serious safety and health violations. The Occupational Safety and Health Administration cited Guam Industrial Services Inc., doing business as Guam Shipyard, with 61 safety and health violations at its Santa Rita facility, 46 of which were serious violations and 7 repeat. Proposed fines totaled $293,450. Source: https://www.osha.gov/pls/oshaweb/owadisp.show_document?p_table=NEWS_RELEA SES&p_id=24471 For another story, see item 2 [Return to top] Defense Industrial Base Sector Nothing to report [Return to top] Financial Services Sector 6. August 1, Associated Press – (New York) FBI: 2 arrested in NY in $100 million Ponzi scheme. An investment fund manager and his brother-in-law were arrested and charged with allegedly running a $100 million Ponzi scheme that used investors’ money for personal investments in a Long Island resort. Source: http://www.sfgate.com/news/crime/article/FBI-2-arrested-in-NY-in-100million-Ponzi-scheme-4700418.php 7. August 1, Associated Press – (National) Ex-Goldman trader found liable in mortgage fraud. A former trader at Goldman Sachs was found liable in a U.S. Securities and Exchange Commission lawsuit for misleading investors about subprime mortgage securities during the 2007 mortgage crisis, making $1 billion in profits for his employer. Source: http://www.nbcnews.com/business/ex-goldman-trader-fabulous-fab-foundliable-mortgage-fraud-6C10820781 8. August 1, Baltimore Sun – (Maryland) Baltimore resident convicted in financial fraud schemes. A Baltimore man was convicted of defrauding the Internal Revenue Service and credit unions in a variety of schemes that included receiving $12 million in fraudulent tax credits and over $370,000 in fraudulent tax refunds. Source: http://www.baltimoresun.com/news/maryland/crime/blog/bs-md-ci-tax-fraudconviction-20130801,0,6358076.story -3- [Return to top] Transportation Systems Sector 9. August 2, Newport News Daily Press – (Virginia) Tanker truck accident shuts down I-64 west at J. Clyde Morris Blvd. Thursday. An overturned tanker hauling asphalt sealer closed Interstate 64 westbound in Newport News for 7 hours August 1. The impact of the crash ruptured the trucks tank, causing the sealer to leak onto the highway. Source: http://www.dailypress.com/news/breaking/dp-hazmat-spill-blocks-i64westbound-at-j-clyde-morris-boulevard-exit-20130801,0,3804214.story 10. August 2, KMSP 9 Minneapolis-St. Paul – (Minnesota) Tanker fire shuts down Hwy 52 near Koch Refinery. Authorities shut down Highway 52 near the Koch Refinery in Rosemount for over 5 hours August 2 after a semi-truck rolled over and burst into flames. Source: http://www.myfoxtwincities.com/story/23027131/tanker-fire-shuts-down-hwy52-near-koch-refinery 11. August 1, WTVB 1590AM Coldwater – (Michigan) Nearly two dozen injured in Greyhound bus accident on I-94 Thursday morning. Authorities closed the westbound lanes of Interstate 94 in Climax, Michigan, after a Greyhound bus collided with a semi-truck August 1. Nearly two dozen were injured following the incident. Source: http://wincountry.com/news/articles/2013/aug/02/nearly-two-dozen-injured-ingreyhound-bus-accident-on-i-94-thursday-morning/ 12. August 1, Black Hills Pioneer – (South Dakota) Semi accident causes two-hour closure in Canyon. A section of Highway 14A in Spearfish was closed for around 2 hours after a semi carrying a truckload of round hay bails tipped on its side. Source: http://www.bhpioneer.com/local_news/article_be686a96-fac1-11e2-9e41001a4bcf887a.html 13. August 1, KMVT 11 Twin Falls – (Idaho) Police release details to fatal accident between Wendell and Gooding. A fatal two-vehicle accident blocked both directions of State Highway 46 between Wendell and Gooding for approximately 3 hours August 1. Source: http://www.kmvt.com/news/breakingalert/Fatal-Accident-Closes-Highway-46Between-Wendell-and-Gooding-217920181.html 14. August 1, KTVB 7 Boise – (Idaho) Weiser man dies in crash on Highway 95. A fatal two-vehicle crash closed the northbound lane of Highway 95 near New Meadows for around 5 hours August 1. Source: http://www.ktvb.com/news/State-Police-investigating-fatal-crash-on-Highway95-218011521.html -4- 15. August 1, WGHP 8 High Point – (North Carolina) Multiple accidents snarl traffic on Business 40 in Winston-Salem. Severe weather caused multiple accidents and closed all lanes on Business 40 in Winston-Salem for over 2 hours August 1. Source: http://myfox8.com/2013/08/01/multiple-car-accident-on-business-40-inwinston-salem/ 16. August 1, WKYT 27 Lexington – (Kentucky) Woman dies after SUV hits semi on U.S. 62 in Scott County. A fatal accident closed U.S. Route 62 in Scott County for several hours August 1. Source: http://www.wkyt.com/news/headlines/Deadly-crash-closes-US-62-in-ScottCounty-217933881.html 17. August 1, KUSA 9 Denver – (Colorado) 1 dead, 4 injured in Colorado highway crash. A fatal two-vehicle crash closed Highway 285 in Jefferson County for several hours August 1. Source: http://www.9news.com/news/local/article/348177/346/1-killed-4-injured-inColorado-highway-crash For another story, see item 26 [Return to top] Food and Agriculture Sector 18. August 1, Los Angeles Times – (California) Ontario food processer fined $157,000 for toxic ammonia leaks. Ventura Foods, an Ontario, California, food processing plant operator, agreed to pay $157,000 in fines in connection with a release of toxic ammonia. Ventura Foods was cited for failing to immediately notify authorities after its equipment leaked anhydrous ammonia and for deficiencies in its accident prevention and emergency response plans. Source: http://www.latimes.com/news/science/sciencenow/la-sci-sn-toxic-ammoniaontario-food-processing-plant-20130801,0,4562369.story [Return to top] Water and Wastewater Systems Sector 19. August 1, City of Valdosta – (Georgia) Valdosta wastewater plant spills 7.2 million gallons. The city of Valdosta reported continued heavy rains caused the Withlacoochee Wastewater Treatment Plant to discharge approximately 7.2 million gallons of total suspended solids. The plant is currently undergoing relocation and working towards bringing the facility in compliance with the National Pollutant Discharge Elimination System permit. Source: http://www.wctv.tv/news/headlines/Withlacoochee-217994401.html 20. August 1, Associated Press – (South Dakota) Strange odor, taste in Aberdeen water fixed. Aberdeen, South Dakota, officials reported an equipment problem that caused -5- the city’s water to have an odd smell and taste for several weeks was fixed and should return to normal in a week or two. The problem stemmed from equipment that was not providing enough additives to deal with algae that formed in the city’s main source of water, the Elm River. Source: http://www.argusleader.com/viewart/20130801/UPDATES/308010044/Strange-odortaste-Aberdeen-water-fixed 21. July 31, Hickory Daily Record – (North Carolina) Rains cause weekend wastewater spill in Burke County. Burke County officials issued a public notice reporting a 140,000 gallon wastewater spill July 27 from a manhole outside the Indian Hills Pump Station spilled into the Catawba River Basin. County officials reported the area has been the source of multiple previous spills which are related to inflow and infrastructure problems which are being addressed. Source: http://www.hickoryrecord.com/news/article_63417996-fa1c-11e2-a186001a4bcf6878.html For another story, see item 29 [Return to top] Healthcare and Public Health Sector 22. August 1, SC Magazine – (International) Black Hat: Diabetic researcher finds insulin pump glitch that almost killed him. A diabetic security researcher with InGuardians revealed a memory storage flaw in his insulin pump occurred after a battery change and greatly skewed the amount of insulin he needed to manage his blood glucose levels. The insulin pump could forget important data stored in it after the change, and lead its user to mistakenly intake too much insulin. Source: http://www.scmagazine.com//black-hat-diabetic-researcher-finds-insulinpump-glitch-that-almost-killed-him/article/305483/ 23. August 1, Boston Globe – (Massachusetts) Patients were exposed to hepatitis B because nurses lacked access to electronic medical records. A Massachusetts health department investigation concluded dialysis patients at Boston Medical Center were exposed to hepatitis B in March because nurses did not have access to computerized medical records that would have notified them if a patient was infected. Due to the lack of awareness of the patient’s infection, nurses failed to properly clean dialysis machines before using them on 13 other patients over a 2-week period. Source: http://www.boston.com/whitecoatnotes/blogs/white-coatnotes/2013/08/01/patients-were-exposed-hepatitis-because-nurses-lacked-accesselectronic-medical-records/LUA8CenF0AOERyfnEmEebO/blog.html [Return to top] -6- Government Facilities Sector 24. August 2, Associated Press – (Oklahoma) Oklahoma courthouse evacuated after chemical spill. A chemical spill near the Sequoyah County courthouse in Sallisaw prompted the courthouse’s closure August 1 as the building was evacuated after a milky-white chemical started leaking from a truck parked near the courthouse. Officials determined the chemical was a non-hazardous solvent. Source: http://newsok.com/oklahoma-courthouse-evacuated-after-chemicalspill/article/3868415 25. August 2, Modesto Bee – (California) Local strike team heads to Aspen Fire. Firefighters reached 45 percent containment of the 16,200-acre Aspen Fire in Fresno County August 1. Smoke from the fire combined with smoke from wildfires in Oregon caused unhealthy air in the Northern San Joaquin Valley as nearly 1,900 firefighters battled the blaze. Source: http://www.modbee.com/2013/08/02/2841424/local-strike-team-heads-toaspen.html 26. August 1, Redding Record Searchlight – (California) 1,200 acres ablaze in Klamath National Forest. Crews battled two fires in the Klamath National Forest that burned 1,200 acres along the Salmon River in Siskiyou County. The fires have led to the closure of Highway 93 near Butler Flat. Source: http://www.redding.com/news/2013/aug/01/fires-burning-klamath-nationalforest/ 27. August 1, Wenatchee World – (Washington) Fire crews heading to Kittitas County to corral Colockum Tarps fire. Crews continued to battle the 72,000-acre Colockum Tarps Fire in Kittitas County August 1 and evacuations were ordered for several other residences around the county while firefighters worked to establish containment lines. Source: http://www.wenatcheeworld.com/news/2013/aug/01/fire-crews-heading-tokittitas-county-to-corral-colockum-tarps-fire/ 28. August 1, Associated Press – (Pennsylvania) Fire destroys York County municipal building. One firefighter was injured battling a blaze at a York County municipal building August 1. The cause of the fire is under investigation and the facility and its contents were a complete loss. Source: http://www.timesunion.com/news/article/Fire-destroys-York-Countymunicipal-building-4700347.php 29. August 1, Associated Press – (Maryland) OSHA finds safety violations at Army pond. The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) found several violations August 1 at an Army weapons-testing pond in Aberdeen, Maryland, where 3 people have died in 2013. OSHA began its investigation after a civilian technician died while performing routine maintenance in the pond January 30. Source: http://www.nbc12.com/story/22995117/osha-finds-safety-violations-at-army- -7- pond 30. August 1, New York Times – (International) Terror threat prompts U.S. to close diplomatic missions. Officials with the U.S. Department of State announced August 1 the closure of dozens of American diplomatic facilities all over the world for the weekend of August 3 due to a terrorism threat. Source: http://www.nytimes.com/2013/08/02/us/some-american-embassies-to-close-onsunday-over-security-concerns.html For another story, see item 34 [Return to top] Emergency Services Sector 31. August 2, KSHB 41 Kansas City – (Kansas) Authorities divert 911 calls during outage. Emergency calls from Miami, Douglas, and Franklin Counties in Kansas were rerouted to the Wellsville Police Department for roughly 8 hours August 1 when a construction crew struck a fiber line, cutting 9-1-1 services. Source: http://www.kshb.com/dpp/news/state/kansas/authorities-divert-911-callsduring-outage 32. August 1, Florence Morning News – (South Carolina) Fire knocks out Williamsburg County emergency phone lines. Williamsburg County rerouted their 9-1-1 calls to Clarendon County’s Emergency Services department August 1after a business fire damaged a phone line which carried 9-1-1 calls. Frontier Communications worked to restore service and repair the damaged communications line. Source: http://www.scnow.com/news/local/article_efbe8e6a-fac4-11e2-9c3d001a4bcf6878.html 33. August 1, Newport Patch – (Rhode Island) Woman injures husband, crashes into emergency vehicles. A Kentucky woman was charged after crashing her car into a police cruiser and fire department vehicle August 1 in Newport, causing significant damage. The woman resisted arrest before being handcuffed and her husband told an officer that they had been drinking. Source: http://newport.patch.com/groups/police-and-fire/p/woman-injures-husbandcrashes-into-emergency-vehicles [Return to top] Information Technology Sector 34. August 2, CNET – (International) Comfoo cyberspy campaign still active. Dell SecureWorks found in a report that the Comfoo cyberespionage campaign is still actively targeting corporate and government systems worldwide, and found over 200 variants of the malware. Source: http://news.cnet.com/8301-1009_3-57596706-83/comfoo-cyberspy-campaign- -8- still-active/ 35. August 2, Softpedia – (International) Opscode wiki and ticketing systems hacked, user data compromised. Opscode, developer of the Chef software configuration management tool, warned customers that attackers gained access to its wiki and ticketing user database, compromising usernames, emails, names, and hashed passwords. Source: http://news.softpedia.com/news/Opscode-Wiki-and-Ticketing-SystemsHacked-User-Data-Compromised-372668.shtml 36. August 2, Softpedia – (International) Flaws in UEFI implementation can be abused to bypass Windows 8 Secure Boot. Three researchers presented two techniques at the Black Hat 2013 conference that can bypass the Secure Boot system in Windows 8 by using a firmware vulnerability or vulnerabilities in common applications. Source: http://news.softpedia.com/news/Flaws-in-UEFI-Implementation-Can-BeAbused-to-Bypass-Windows-8-Secure-Boot-372798.shtml 37. August 2, Softpedia – (International) JavaScript attacks can be used to steal web browser data, experts warn. A researcher presenting at the Black Hat 2013 conference demonstrated a method to gain access to a Web page’s source code by exploiting browser and JavaScript flaws. Source: http://news.softpedia.com/news/JavaScript-Attacks-Can-Be-Used-to-StealWeb-Browser-Data-Experts-Warn-372786.shtml 38. August 2, Help Net Security – (International) FBI announces cyberattack-reporting portal for private sector companies. The FBI launched a pilot program for private sector companies to report cyber threats called iGuardian. The program is initially open to companies that are part of the InfraGuard network and may eventually be opened to others. Source: https://www.net-security.org/secworld.php?id=15347 39. August 1, V3.co.uk – (International) Businesses warned to prepare for evolved Andromeda botnet. Researchers at TrendMicro found that the authors of the Andromeda botnet are about to release a major update to the botnet, including bug fixes and new plugins. Source: http://www.v3.co.uk/v3-uk/news/2286354/businesses-warned-to-prepare-forevolved-andromeda-botnet For another story, see item 3 Internet Alert Dashboard To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or visit their Web site: http://www.us-cert.gov Information on IT information sharing and analysis can be found at the IT ISAC (Information Sharing and Analysis Center) Web site: https://www.it-isac.org -9- [Return to top] Communications Sector Nothing to report [Return to top] Commercial Facilities Sector 40. August 2, Associated Press – (Washington) Seattle Fire: ‘unknown odor’ prompts evacuation of Seattle apartment units; no hazard found. An unknown odor at a north Seattle apartment building August 1 prompted the building to evacuate its 21 units until the building could be ventilated. Residents were allowed to return August 2. Source: http://www.dailyjournal.net/view/story/d58e0a19fb204a45895b65e74a78417e/WA-Apartments-Evacuated/ 41. July 31, Burlington County Times – (Pennsylvania) Moorestown Mall and East Gate shopping center evacuated after morning gas leak. Emergency officials evacuated the Moorestown Mall and several nearby stores at East Gate Square shopping center July 31 for 3 hours after a natural gas line ruptured by a construction crew performing renovations. Source: http://www.phillyburbs.com/news/local/burlington_county_times_news/moorestownmall-and-east-gate-shopping-center-evacuated-after-morning/article_0f48e923-0b1158a4-bac0-f84e75eb2e1e.html [Return to top] Dams Sector 42. August 1, Associated Press – (New Mexico) Lake Roberts dam in NM undergoing renovation. The Silver City dam in New Mexico will lower the water level at Lake Roberts for a $6.5 million renovation to its dam and spillway to strengthen it and reduce its vulnerability to flooding. The boat ramp will be closed as the water level drops and the dam will be raised 8 feet, the current spillway will be replaced, and a secondary spillway will be built. Source: http://www.lcsun-news.com/las_cruces-news/ci_23772727/lake-roberts-damnm-undergoing-renovation [Return to top] - 10 - Department of Homeland Security (DHS) DHS Daily Open Source Infrastructure Report Contact Information About the reports - The DHS Daily Open Source Infrastructure Report is a daily [Monday through Friday] summary of open-source published information concerning significant critical infrastructure issues. The DHS Daily Open Source Infrastructure Report is archived for 10 days on the Department of Homeland Security Web site: http://www.dhs.gov/IPDailyReport Contact Information Content and Suggestions: Send mail to cikr.productfeedback@hq.dhs.gov or contact the DHS Daily Report Team at (703) 942-8590 Subscribe to the Distribution List: Visit the DHS Daily Open Source Infrastructure Report and follow instructions to Get e-mail updates when this information changes. Removal from Distribution List: Send mail to support@govdelivery.com. Contact DHS To report physical infrastructure incidents or to request information, please contact the National Infrastructure Coordinating Center at nicc@hq.dhs.gov or (202) 282-9201. To report cyber infrastructure incidents or to request information, please contact US-CERT at soc@us-cert.gov or visit their Web page at www.us-cert.gov. Department of Homeland Security Disclaimer The DHS Daily Open Source Infrastructure Report is a non-commercial publication intended to educate and inform personnel engaged in infrastructure protection. Further reproduction or redistribution is subject to original copyright restrictions. DHS provides no warranty of ownership of the copyright, or accuracy with respect to the original source material. - 11 -